White House Reviewing OSHA’s Proposed Rule on Infectious Diseases
The White House Office of Information and Regulatory Affairs is conducting a final review of an Occupational Safety and Health Administration (OSHA) proposed rule that seeks to introduce new standards to better protect workers from infectious disease hazards such as COVID-19, SARS, tuberculosis, measles, varicella disease, and MRSA. The new standards will apply to healthcare and other occupational settings where employees face an increased risk of exposure to infectious diseases including nursing homes, homeless shelters, drug treatment programs, correctional facilities, coroners’ offices, mortuaries, emergency response facilities, and laboratories that handle materials that may be a source of pathogens. The new rule has been a long time coming. OSHA issued its initial Request for Information in May 2010, analyzed comments the same year, and held stakeholder meetings in July 2011, then the proposed rule stalled until 2014 when SBREFA was initiated and completed. OSHA has been examining regulatory alternatives for control measures to protect workers against infections disease...
Texas Hospitals Must Ask Patients About Their Citizenship Status
In August, Texas Governor Greg Abbott issued an Executive Order (GA-46) directing the Texas Health and Human Services Commission (HHSC) to start collecting information on patients who are not lawfully present in the United States and assess costs to the Texas public hospital system. “Texas will hold the Biden-Harris Administration accountable for the consequences of their open border policies, and we will fight to ensure that they pay back Texas for their costly and dangerous policies,” said Governor Abbott. The Executive Order took effect on November 1, 2024. While the Executive Order specifically mentions public hospitals, most private hospitals in Texas must also comply with this new requirement. The Executive Order states that hospitals covered by the executive order include acute care hospitals enrolled in Medicaid or the Children’s Health Insurance Program (CHIP), and the order also applies to other healthcare providers identified by the Health and Human Services Commission. Any hospital that fails to comply with the Executive Order could potentially be expelled from the...
Almost 39,000 Patients Affected by Email Breach at Oklahoma Spine Hospital
Unauthorized email account access has been detected by Oklahoma Spine Hospital, Familylinks, and the Massachusetts Department of Developmental Services and an emailing error by a Missouri Department of Mental Health employee resulted in the impermissible disclosure of patient data. Oklahoma Spine Hospital Oklahoma Spine Hospital in Oklahoma City has warned 38,945 patients about the exposure of some of their protected health information. Suspicious activity was identified in an employee’s email account on or around July 1, 2024. Immediate action was taken to secure its email tenant, and an investigation was launched to determine the nature and scope of the breach. The forensic investigation confirmed on September 24, 2024, that patients’ protected health information was stored in the compromised accounts including first and last names, dates of birth, financial account numbers and routing numbers, health insurance information, medical information, payment card information, and driver’s license information. At the time of issuing notifications, Oklahoma Spine Hospital was unaware of...
TriHealth Physician Partners Confirms Patient Data Exposed in Cyberattack
Cyberattacks have recently been announced by TriHealth Physician Partners in Ohio and Harmac Medical Products in New York, and an insider breach has been discovered by North Texas Medical Specialists. TriHealth Physician Partners TriHealth, dba TriHealth Physician Partners (TriHealth), a primary care provider serving the greater Cincinnati area of Ohio, has warned patients about a security incident at one of its business associates that involved unauthorized access to patients’ protected health information. TriHealth said it learned about the incident at its vendor on October 23, 2024, and confirmed that there was no unauthorized access to its own network. The forensic investigation confirmed the attacker only had access to historical documents related to care provided by the OB/GYN group, For Women, prior to January 2020 when For Women joined TriHealth. An analysis of the affected files confirmed they contained names, addresses, dates of birth, Social Security numbers, claims information, medical conditions, medications, lab results, and other treatment information. TriHealth is...
Great Plains Regional Medical Center: 133,000 Patients Affected by Ransomware Attack
Great Plains Regional Medical Center in Elk City, OK, has fallen victim to a ransomware attack. The attack was detected on September 8, 2024, when files were encrypted. A third-party cybersecurity firm was engaged to assist with the investigation and determined that access was gained to its network on September 5, 2024, and continued until the incident was detected on September 8. Prior to encrypting files, the threat actor exfiltrated data from its systems that included names, demographic information, health insurance information, driver’s license numbers, clinical treatment information such as diagnosis and medication information, and Social Security numbers. Great Plains Regional Medical Center said it was able to quickly restore access to its systems, return to normal operations, and recover most of the encrypted data; however, a limited amount of patient data could not be recovered. Great Plains Regional Medical Center did not disclose the name of the ransomware group. The ransomware attack has recently been reported to the HHS’ Office for Civil Rights as involving the...



